File name:

_2368e264cafd9c6699c2ef958e873926b7f7575e52318c705127a166e4ab53dc.exe

Full analysis: https://app.any.run/tasks/13458b17-0471-4be8-a756-7c480ab641ad
Verdict: Malicious activity
Threats:

Amadey is a formidable Windows infostealer threat, characterized by its persistence mechanisms, modular design, and ability to execute various malicious tasks.

Analysis date: May 07, 2026, 21:10:38
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
amadey
botnet
stealer
golang
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

8B3C9E5BDD95E9229BC55546E447F864

SHA1:

E5F3933D87FF5932469EEC207F01660083A57CC4

SHA256:

2368E264CAFD9C6699C2EF958E873926B7F7575E52318C705127A166E4AB53DC

SSDEEP:

49152:Wf16I4RmNwut2UN6eDHEv5esRC7DOnQTeWzWRttBAZ7bAbwK4ASAKs4dKkwkVseT:3I4RMwu6HflgR8Rmd4NO3bCsk9c

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • _2368e264cafd9c6699c2ef958e873926b7f7575e52318c705127a166e4ab53dc.exe (PID: 7780)
      • Bwale.exe (PID: 7448)
      • Bwale.exe (PID: 7316)
      • Bwale.exe (PID: 2016)
      • Bwale.exe (PID: 8104)
    • AMADEY has been detected (SURICATA)

      • Bwale.exe (PID: 7448)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • _2368e264cafd9c6699c2ef958e873926b7f7575e52318c705127a166e4ab53dc.exe (PID: 7780)
    • Starts itself from another location

      • _2368e264cafd9c6699c2ef958e873926b7f7575e52318c705127a166e4ab53dc.exe (PID: 7780)
    • Contacting a server suspected of hosting an CnC

      • Bwale.exe (PID: 7448)
    • The process executes via Task Scheduler

      • Bwale.exe (PID: 7316)
      • Bwale.exe (PID: 2016)
      • Bwale.exe (PID: 8104)
  • INFO

    • Checks supported languages

      • _2368e264cafd9c6699c2ef958e873926b7f7575e52318c705127a166e4ab53dc.exe (PID: 7780)
      • Bwale.exe (PID: 7448)
      • Bwale.exe (PID: 8104)
      • Bwale.exe (PID: 2016)
      • Bwale.exe (PID: 7316)
    • Create files in a temporary directory

      • _2368e264cafd9c6699c2ef958e873926b7f7575e52318c705127a166e4ab53dc.exe (PID: 7780)
    • Reads the computer name

      • _2368e264cafd9c6699c2ef958e873926b7f7575e52318c705127a166e4ab53dc.exe (PID: 7780)
      • Bwale.exe (PID: 7448)
    • Process checks computer location settings

      • _2368e264cafd9c6699c2ef958e873926b7f7575e52318c705127a166e4ab53dc.exe (PID: 7780)
    • Reads security settings of Internet Explorer

      • _2368e264cafd9c6699c2ef958e873926b7f7575e52318c705127a166e4ab53dc.exe (PID: 7780)
      • Bwale.exe (PID: 7448)
    • Application based on Golang

      • Bwale.exe (PID: 7448)
    • There is functionality for taking screenshot (YARA)

      • Bwale.exe (PID: 7448)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (41)
.exe | Win64 Executable (generic) (36.3)
.dll | Win32 Dynamic Link Library (generic) (8.6)
.exe | Win32 Executable (generic) (5.9)
.exe | Win16/32 Executable Delphi generic (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 0000:00:00 00:00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 3
CodeSize: 945664
InitializedDataSize: 16384
UninitializedDataSize: -
EntryPoint: 0x66fc0
OSVersion: 6.1
ImageVersion: 1
SubsystemVersion: 6.1
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
137
Monitored processes
5
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start _2368e264cafd9c6699c2ef958e873926b7f7575e52318c705127a166e4ab53dc.exe #AMADEY bwale.exe bwale.exe no specs bwale.exe no specs bwale.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2016"C:\Users\admin\AppData\Local\Temp\adb7f46c0c\Bwale.exe"C:\Users\admin\AppData\Local\Temp\adb7f46c0c\Bwale.exesvchost.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\adb7f46c0c\bwale.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\bcryptprimitives.dll
c:\windows\syswow64\powrprof.dll
7316"C:\Users\admin\AppData\Local\Temp\adb7f46c0c\Bwale.exe"C:\Users\admin\AppData\Local\Temp\adb7f46c0c\Bwale.exesvchost.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\adb7f46c0c\bwale.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\bcryptprimitives.dll
c:\windows\syswow64\powrprof.dll
7448"C:\Users\admin\AppData\Local\Temp\adb7f46c0c\Bwale.exe" C:\Users\admin\AppData\Local\Temp\adb7f46c0c\Bwale.exe
_2368e264cafd9c6699c2ef958e873926b7f7575e52318c705127a166e4ab53dc.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\adb7f46c0c\bwale.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\bcryptprimitives.dll
7780"C:\Users\admin\Desktop\_2368e264cafd9c6699c2ef958e873926b7f7575e52318c705127a166e4ab53dc.exe" C:\Users\admin\Desktop\_2368e264cafd9c6699c2ef958e873926b7f7575e52318c705127a166e4ab53dc.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\_2368e264cafd9c6699c2ef958e873926b7f7575e52318c705127a166e4ab53dc.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\bcryptprimitives.dll
8104"C:\Users\admin\AppData\Local\Temp\adb7f46c0c\Bwale.exe"C:\Users\admin\AppData\Local\Temp\adb7f46c0c\Bwale.exesvchost.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\adb7f46c0c\bwale.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\bcryptprimitives.dll
c:\windows\syswow64\powrprof.dll
Total events
0
Read events
0
Write events
0
Delete events
0

Modification events

No data
Executable files
1
Suspicious files
1
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
7780_2368e264cafd9c6699c2ef958e873926b7f7575e52318c705127a166e4ab53dc.exeC:\Windows\Tasks\Bwale.jobbinary
MD5:A5E09635C6BF78D7FE5A1B0BC498B642
SHA256:7C1D2053A782EB8F17F88894BBEFB5BF80CE2103E663DCD9F9B2910BD87DEF06
7780_2368e264cafd9c6699c2ef958e873926b7f7575e52318c705127a166e4ab53dc.exeC:\Users\admin\AppData\Local\Temp\adb7f46c0c\Bwale.exeexecutable
MD5:8B3C9E5BDD95E9229BC55546E447F864
SHA256:2368E264CAFD9C6699C2EF958E873926B7F7575E52318C705127A166E4AB53DC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
53
TCP/UDP connections
39
DNS requests
18
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5276
MoUsoCoreWorker.exe
GET
304
40.127.240.158:443
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?ProcessorClockSpeed=3094&FlightIds=&UpdateOfferedDays=4294967295&BranchReadinessLevel=CB&OEMManufacturerName=DELL&IsCloudDomainJoined=0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&sku=48&ActivationChannel=Retail&AttrDataVer=186&IsMDMEnrolled=0&ProcessorCores=6&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&TotalPhysicalRAM=6144&PrimaryDiskType=4294967295&FlightingBranchName=&ChassisTypeId=1&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&sampleId=95271487&deviceClass=Windows.Desktop&App=muse&DisableDualScan=0&AppVer=10.0&OEMSubModel=J5CR&locale=en-US&IsAlwaysOnAlwaysConnectedCapable=0&ms=0&DefaultUserRegion=244&UpdateServiceUrl=http%3A%2F%2Fneverupdatewindows10.com&osVer=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&DeferQualityUpdatePeriodInDays=0&ring=Retail&DeferFeatureUpdatePeriodInDays=30
US
whitelisted
6628
SIHClient.exe
GET
304
135.232.92.137:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
7784
svchost.exe
GET
200
23.52.181.212:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
814 b
whitelisted
7784
svchost.exe
GET
200
23.216.77.42:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
7448
Bwale.exe
POST
200
91.92.242.236:80
http://91.92.242.236/oPvjr94jfe/index.php
SC
text
8 b
malicious
7784
svchost.exe
GET
200
40.127.240.158:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/WaaSAssessment?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&ring=Retail&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=10.0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=WaaSAssessment&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&ServicingBranch=CB&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&HonorWUfBDeferrals=0&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
text
5.80 Kb
whitelisted
7448
Bwale.exe
POST
200
91.92.242.236:80
http://91.92.242.236/oPvjr94jfe/index.php
SC
binary
1 b
malicious
5316
svchost.exe
POST
400
20.190.159.129:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
204 b
whitelisted
5316
svchost.exe
POST
200
20.190.159.129:443
https://login.live.com/RST2.srf
US
xml
1.24 Kb
whitelisted
5316
svchost.exe
POST
400
20.190.159.129:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
204 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5276
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
7784
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
48.192.1.64:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
5276
MoUsoCoreWorker.exe
23.216.77.42:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
7784
svchost.exe
23.216.77.42:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
5276
MoUsoCoreWorker.exe
23.52.181.212:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
7784
svchost.exe
23.52.181.212:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
7448
Bwale.exe
91.92.242.236:80
OMEGATECH-AS
SC
malicious

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
activation-v2.sls.microsoft.com
  • 48.192.1.64
whitelisted
google.com
  • 142.251.110.138
  • 142.251.110.139
  • 142.251.110.102
  • 142.251.110.113
  • 142.251.110.100
  • 142.251.110.101
whitelisted
crl.microsoft.com
  • 23.216.77.42
  • 23.216.77.25
  • 23.216.77.28
  • 23.216.77.36
  • 23.216.77.20
  • 23.216.77.6
  • 23.216.77.30
  • 23.216.77.22
whitelisted
www.microsoft.com
  • 23.52.181.212
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 20.190.159.129
  • 20.190.159.64
  • 20.190.159.75
  • 40.126.31.130
  • 40.126.31.67
  • 40.126.31.128
  • 20.190.159.128
  • 20.190.159.73
whitelisted
slscr.update.microsoft.com
  • 135.232.92.137
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 74.178.76.54
whitelisted
self.events.data.microsoft.com
  • 20.189.173.11
whitelisted

Threats

PID
Process
Class
Message
7448
Bwale.exe
Misc activity
INFO [ANY.RUN] Connection to IP from commonly abused ASN (AS214943 RAILNET)
7448
Bwale.exe
Malware Command and Control Activity Detected
BOTNET [ANY.RUN] Amadey HTTP POST Request (st=s)
7448
Bwale.exe
Misc Attack
ET DROP Spamhaus DROP Listed Traffic Inbound group 14
7448
Bwale.exe
Malware Command and Control Activity Detected
ET MALWARE Amadey CnC Response
No debug info